30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Assertions AHS01-03 AFR01-03 AFR01-04, AIC02 Passed<br />

Others are N/A<br />

Pass Rate<br />

(%)<br />

78.95% 15.79% 28.57% 78.95%<br />

Instead <strong>of</strong> reporting that the partition was partially hidden, FTK Imager reported to the<br />

user that imaging failed with error <strong>of</strong> “block index out <strong>of</strong> bounds”. FTK Imager froze<br />

at the stage <strong>of</strong> preparing to create image, when the program was trying to acquire the<br />

completely hidden FAT32 partition (see Sections 1.26 and 1.27 in Appendix 7).<br />

Helix 3 Pro was not able to complete the entire imaging process. In the test case<br />

TC-12(1) <strong>of</strong> partially hidden area, Helix 3 Pro was acquiring the image at an<br />

extremely slow speed. The imaging process was stopped by the tester 20 hours into the<br />

imaging process since the time <strong>for</strong> imaging an 80GB hard drive was considered<br />

unreasonable. In the case where the partition was completely hidden, Helix 3 Pro was<br />

not able to recognise the partition table <strong>of</strong> the hidden partition.<br />

AIR was not able to detect and acquire the hidden data in the test drive. In the<br />

test <strong>of</strong> partially hidden partition, AIR was able to acquire all the accessible data<br />

correctly. On the other hand, AIR tool stopped instantly when it attempted to acquire<br />

the completely hidden partition.<br />

4.2.2.11 TC-13: Acquiring Overlapping Partitions<br />

Test case TC-13 involved testing whether the disk imaging tools were able to acquire<br />

two partitions that had overlapping boundaries (The ending address <strong>of</strong> partition A was<br />

positioned after the starting address <strong>of</strong> Partition B). Table 4.13 shows the test results <strong>of</strong><br />

test case TC-13.<br />

FTK Imager was able to recover the partition table and display the correct<br />

in<strong>for</strong>mation to the user. All the data acquired were correct and complete. However, the<br />

irregularity <strong>of</strong> the partition table was not reported to the user.<br />

82

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!